SecurityWorldMarket

30/07/2018

Ensuring easy configuration of GDPR compliant video

Regensburg, Germany

The EU General Data Protection Regulation (EU GDPR) affirms the great importance of data protection and data security, but does not spell out any regulations relating specifically to video security systems. With the 14 functions of the Dallmeier module, businesses can configure their video systems individually so that each is compliant with the requirements of the EU GDPR.

With regard to data protection, which is to say the safeguarding of data protection principles and the rights of data subjects, Dallmeier offers four components, specifically the pixellation of entire individuals by “people masking”, the setup of “private zones” in the captured image to render public areas invisible for example, and the definition of the maximum storage duration for each camera. Optionally, Dallmeier customers can also use a detailed virtual 3D simulation as early as the project planning stage to define which areas are not significant for data protection purposes due to image quality.

For the requirements of data security, i.e. the protection of confidential or personal data from manipulation, loss or unauthorised access, the Dallmeier module offers ten functions in all. On the network level, the Dallmeier module provides authentication according to IEEE 802.1X, end-to-end encryption with TLS 1.2 / 256-bit AES in current Dallmeier systems, and with the “Viproxy” function, Dallmeier recording appliances fulfil the role of security gateway for the video system. Furthermore, all hardware, software and firmware solutions are developed in-house, which eliminates the possibility of hidden access through backdoors.

On the recording level, compliance with EU GDPR regulations is guaranteed by the optional “dual control principle” for viewing recordings, the specification of recording time for each user group with “Maxview” and user group administration via AD/LDAP. Reliable detection and prevention of connection attempts is assured by the “Fail2ban” function, corresponding failover and redundancy mechanisms during recording protect against data losses. Finally, LGC certification ensures that all criteria for judicial usability are fulfilled in the preservation of evidence.

“It is no secret that the ultimate interpretation of the EU GDPR in practical implementation is in no way defined conclusively and will continue to be debated and defined intensely by the national and European data protection oversight authorities until long after the end of 2018”, says Jürgen Seiler, managing director of the Dallmeier consulting subsidiary David IT. “Consequently, the best and simplest way to approach video security is to implement solutions which already provide the answers to all of the requirements that can be anticipated. With the 14 functions of our combined data protection and data security module, customers receive access to precisely this functional range in a form which is easy to both manage and configure.”


Tags


Product Suppliers
Back to top